Category: Uncategorized
-

Two High-Risk Security Flaws Discovered in Curl Library – New Patches Released [email protected] (The Hacker News)
Patches have been released for two security flaws impacting the Curl data transfer library, the most severe of which could potentially result in code execution. The list of vulnerabilities is as follows – CVE-2023-38545 (CVSS score: 7.5) – SOCKS5 heap-based buffer overflow vulnerability CVE-2023-38546 (CVSS score: 5.0) – Cookie injection with none file CVE-2023-38545 is the more severe of…
-
HTTP/2 Rapid Reset Attack
What is HTTP/2? HTTP/2 is a network protocol used by the World Wide Web that reduces latency by allowing multiple concurrent exchanges on the same connection. What is the Attack? A newly identified Distributed Denial-of-Service (DDoS) attack technique is used in the wild. This DDoS attack, known as ‘HTTP/2 Rapid Reset’, leverages a flaw in…
-
Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk Ryan Naraine
Flaw poses a direct threat to the SOCKS5 proxy handshake process in cURL and can be exploited remotely in some non-standard configurations. The post Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk appeared first on SecurityWeek. Read More
-
Payment Card Data Stolen in Air Europa Hack Eduard Kovacs
Spanish airline Air Europa is informing customers that their payment card information has been stolen as a result of a hacker attack. The post Payment Card Data Stolen in Air Europa Hack appeared first on SecurityWeek. Read More
-
Citrix Patches Critical NetScaler ADC, Gateway Vulnerability Ionut Arghire
Citrix has released patches for a critical information disclosure vulnerability in NetScaler ADC and NetScaler Gateway. The post Citrix Patches Critical NetScaler ADC, Gateway Vulnerability appeared first on SecurityWeek. Read More
-

Over 17,000 WordPress Sites Compromised by Balada Injector in September 2023 [email protected] (The Hacker News)
More than 17,000 WordPress websites have been compromised in the month of September 2023 with malware known as Balada Injector, nearly twice the number of detections in August. Of these, 9,000 of the websites are said to have been infiltrated using a recently disclosed security flaw in the tagDiv Composer plugin (CVE-2023-3169, CVSS score: 6.1) that…
-
US Government Releases Security Guidance for Open Source Software in OT, ICS Ionut Arghire
CISA, FBI, NSA, and US Treasury published new guidance on improving the security of open source software in OT and ICS. The post US Government Releases Security Guidance for Open Source Software in OT, ICS appeared first on SecurityWeek. Read More
-

U.S. Cybersecurity Agency Warns of Actively Exploited Adobe Acrobat Reader Vulnerability [email protected] (The Hacker News)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a high-severity flaw in Adobe Acrobat Reader to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Tracked as CVE-2023-21608 (CVSS score: 7.8), the vulnerability has been described as a use-after-free bug that can be exploited to achieve remote code execution (RCE) with theRead More
-

Take an Offensive Approach to Password Security by Continuously Monitoring for Breached Passwords [email protected] (The Hacker News)
Passwords are at the core of securing access to an organization’s data. However, they also come with security vulnerabilities that stem from their inconvenience. With a growing list of credentials to keep track of, the average end-user can default to shortcuts. Instead of creating a strong and unique password for each account, they resort to…
-
Chrome 118 Patches 20 Vulnerabilities Ionut Arghire
Google has released Chrome 118 to the stable channel with patches for 20 vulnerabilities, including one rated ‘critical severity’. The post Chrome 118 Patches 20 Vulnerabilities appeared first on SecurityWeek. Read More
